Solid Oak Software, the Santa Barbara, Calif.-based maker of Web filtering software called CYBERsitter, has confirmed that the Green Dam Youth Escort Web filtering software mandated by the Chinese government includes Solid Oak's proprietary data.
The tip pointed to a report published last week by three University of Michigan computer researchers and DiPasquale said the report proved to be accurate. "We discovered that they had proprietary information about CYBERsitter," she said, citing a list of serial numbers, blacklist files, and DLL files.
She said the company's attorney was in the process of contacting U.S. computer makers to alert them to potential liability arising from the unauthorized use of CYBERsitter code. She said she couldn't provide further details.
The University of Michigan report not only identifies copied CYBERsitter code, but also highlights two major security vulnerabilities in the most recent version of the Green Dam software.
"If Green Dam is deployed in its current form, it will significantly weaken China's computer security," the report concludes. "While the flaws we discovered can be quickly patched, correcting all the problems in the Green Dam software will likely require extensive rewriting and thorough testing. This will be difficult to achieve before China's July 1 deadline for deploying Green Dam nationwide."
According to a report in China Daily on Monday, China's Ministry of Industry and Information Technology has directed the maker of the Green Dam software, Jinhui Computer System Engineering, to patch the security flaws.
In that article, Zhang Chenmin, general manager, denies that his company stole Solid Oak's code. He attributes the similarities in the block lists of the two programs to the fact that both programs are trying to block the same pornographic Web sites.
The Chinese government's Central Propaganda department reportedly has been telling news organizations to stop complaining and to take a more positive tone in stories about Green Dam. Nonetheless, academics and lawyers in China have asked for hearings on the government's Web filtering requirement.
i>InformationWeek Analytics and DarkReading.com have published an independent analysis of security outsourcing. Download the report here (registration required).
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.